Missing Key Policy Definition
Creating KMS keys without defining an explicit key policy, relying on default permissions.
Unrestricted or unintended principals may use, decrypt, or manage the key, enabling data exposure, privilege escalation, or destructive key operations.
Creating KMS keys without defining an explicit key policy, relying on default permissions.
Sourcery automatically identifies authorization bypass due to undefined kms key policy in terraform and many other security issues in your codebase.